Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Amz-Cf-Pop
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
Status
X-AspNetMvc-Version
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Request-ID
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Server-Id
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Cnection
X-Node
X-Readtime
Report-To
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Rq
Server-Timing
X-Response-Time
Feature-Policy
X-CST
X-Rack-Cache
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Rating
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-Server-Name
X-Px
X-Vhost
X-GitHub-Request-Id
X-DataDome
X-ORACLE-DMS-RID
X-VARITI-CCR
RTSS
X-B3-TraceId
X-MS-InvokeApp
X-Ruxit-JS-Agent
X-Cached
X-ESI
X-Goog-Hash
Charset
SPRequestGuid
Accept-CH
X-Server-ID
X-PC
X-Vname
X-TtlSet
Pinterest-Generated-By
X-Mod-Pagespeed
Verso
X-F-Cache
Public-Key-Pins
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Exp-Id
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
X-Dispatcher
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-D2id
X-TTL
X-Version
X-SharePointHealthScore
X-Cdn
X-T
X-Powered-By-Plesk
X-Abt-Application-Version
X-DIS-Request-ID
X-Powered-CMS
X-DynaTrace-JS-Agent
Accept-CH-Lifetime
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Origin-Upstream-Status
X-Forwarded-Proto
X-B
X-Shield-Request-Id
X-Client-IP
X-Recruiting
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MS-Author-Via
X-Amz-Rid
X-Navigation-Version
DynaTrace
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Upstream
Content-MD5
X-Vcap-Request-Id
X-Ttl
Nginx-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-ATIME
AR-CACHE
AR-PoweredBy
Edge-Cache-Tag
X-Oneagent-Js-Injection
Arr-Disable-Session-Affinity
X-N
X-Hits
X-Varnish-Age
X-Debug
X-Oracle-Dms-Rid
TCN
X-Aspnet-Version
X-Goog-Storage-Class
X-NF-Request-ID
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-MSEdge-Ref
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-Id
X-XRDS-Location
X-ATG-Version
S
X-Via-JSL
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
Service-Worker-Allowed
X-NewRelic-App-Data
X-FTR-Expires
X-Logged-In
X-Dns-Prefetch-Control
Alternate-Protocol
X-FastCGI-Cache
Tracecode
X-PressLabs-Stats
Rt-Fastcgi-Cache
X-Forwarded-For
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
Surrogate-Key
X-Kinsta-Cache
X-Cache-Key
X-Content-Digest
AMP-Access-Control-Allow-Source-Origin
X-Pad
Fastly-Restarts
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-FTR-Cache-Host
X-Content-Options
X-Ruxit-Js-Agent
Server-Name
X-Amzn-Trace-Id
X-Edge-Location
X-CF-Powered-By
X-Analytics
Ar-Sid
Backend-Timing
FilterID
X-Grace
Host
TP-L2-Cache
TP-Cache
X-Rid
Fastcgi-Cache
X-Debug-Info
X-User-Agent
X-Whom
X-Magnolia-Registration
X-Hostname
ServerID
X-Cache-2
X-IPLB-Instance
X-Revision
X-B3-Sampled
Eomportal-Instance
X-Page-Id
X-Request-Processing-Time
X-Request-Received
X-Mobile
Paypal-Debug-Id
X-Srv
X-NWS-LOG-UUID
AR-Request-ID
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-HS-Cache-Config
X-VCache
X-Content-Powered-By
Retry-After
X-GUploader-UploadID
X-B-Cache
X-Signature
X-Litespeed-Cache
X-Handled-By
Source
X-LB-Cache
X-Cluster
X-Device-Type
X-Cache-Action
X-SS-Set-Cookie
Refresh
X-WA-Info
X-FB-Debug
X-Instance
X-Cache-Hit
Cleartype
X-Request-Guid
X-App-Environment
X-Cache-Control
X-Varnish-Grace
X-Framework
X-BCube-Filmed-By
X-Tumblr-User
X-Platform-Server
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Webserver
X-Correlation-Id
X-Esi
X-Zen-Fury
Display
X-Middleton-Display
X-Sol
X-Varnish-Backend
X-XRDS-LOCATION
X-Daa-Tunnel
X-Az
X-AppVersion
X-Activity-Id
X-Content-Type
VIX-Pulpo-Node
X-Cache-Server
X-Fastcgi-Cache
VIX-Pulpo-Upstream-Status
Healthy
X-Cache-Rule
X-Varnish-Server
Response
X-Seen-By
X-Wix-Request-Id
ViewerVersion
X-Middleton-Response
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-URL
X-Geo-Country
X-Cached-By
X-Generated-By
S-Cnection
X-App-Server
Cache-Status
Server-Node
X-TT
Upgrade-Insecure-Requests
X-CACHE-GROUP
X-Origin-Server
X-DataStream-Cache-Status
X-Accel-Expires
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amz-Replication-Status
X-Cache-Age
Payment
X-RequestSource
X-Response-Served-From
X-S
X-UA-Device-Type
GEO-INFO
Filters
X-TA-CDN-Provider
X-Cacheable-TTL
X-Locale
X-Node-Name
X-Cache-NE
Viewport
ServedBy
Actual-Object-TTL
X-Servedby
X-Edge-Cache-Key
X-Contextid
Accept-Charset
X-Status
X-Edge-Cache
NGB
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Access-Control-Allow-Method
X-TT-TIMESTAMP
X-Varnish-IP
X-Varnish-Hits
X-Jobs
X-FW-Hash
X-FW-Type
X-FW-Static
X-GeoIP
X-Amz-Server-Side-Encryption
X-WPE-Loopback-Upstream-Addr
X-TX-ID
AsisCache
X-FW-Server
X-FW-Serve
X-UUID
X-Adobe-Loc
X-Adobe-Content
HostName
X-WebKit-CSP-Report-Only
Server-Info
Host-Header
X-Storage
Cache
X-PHP-Backend
X-Aspnetmvc-Version
X-Cache-Remote
X-Cache-TTL-Remaining
Cache-Tv-Group
SRV
X-Rendered-As
X-Croise-Owner
MS-CV
X-Vg-Webcache
From-Origin
X-Hyper-Cache
X-APP-VERSION
X-Region
X-Cache-Operation
X-App-Version
X-Webkit-CSP
X-Redis-Cache
X-HS-Combine-CSS
Cache-Tag
Served-By
Liferay-Portal
Public-Key-Pins-Report-Only
DC
X-Forwarded-Host
X-Mode
Xserver
X-Yottaa-Optimizations
X-Detected-As
Fastcgi-Useragent
Fastcgi-X-Cache
X-Yottaa-Metrics
X-Hosted-By
X-RN-RSRV
Machine
X-Site-Version
Meta-Geo
X-Webstats-RespID
X-Request-Time
X-Loop
Fastcgi-X-Cache-Version
X-Cache-Var-Map
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Agile-Id
Selected-FE
X-Agile-Age
X-Agile
X-Is-Bot
X-Human
X-Generated
X-Cache-Var
X-IP
X-Proxy-Build
X-Timing-Wait
X-Path-Route
X-TNCMS
TWC-Device-Class
Now
Origin-Edge-Control
TWC-Connection-Speed
Origin-Cache-Control
Property-Id
TWC-Privacy
X-Labrador-Cache-Channel
X-CDN-Cache
X-Cache-Category-Id
X-BYPASS-REASON
X-L-Path
X-Environment-Context
X-Web-Node
X-Vgn-Hpd-Reason
X-Upstream-HT
X-Origin-Hint
X-NGENIX-Cache
X-Grey
X-Internal-Host
X-JoinUs
Cache-Name
TWC-Locale-Group
X-ProxyCache-Key
TWC-GeoIP-LatLong
X-Pc-Appver
X-Format
X-Pc-Key
Webcakes-App-Version
Webcakes-Region
X-Upstream-CT
Webcakes-App-Name
X-ProxyCache-Status
X-Pc-Hit
TWC-GeoIP-Country
Powered-By-ChinaCache
X-Akamai-Transformed
X-B3-Spanid
X-NCache
X-Birta-Cache-Post
X-Birta-Served
Cache-Tags
DB-Nickname
X-Section
X-Origin-Host
X-Pubstack
X-PCL
X-Original-Request
X-Access
X-Proxy
X-OCL
S-Rt
X-Via-Fastly
X-Tumblr-Pixel-3
X-Akamai-Request-ID
X-UA
X-Origin-Response-Time
X-Origin
X-VG-TLSProxy
X-Viewer-Country
X-FC-Vary-Parameters
X-Newrelic-App-Data
X-Ocache
X-ServerID
Datacenter
X-Origin-CC
X-Tb
X-ProcessESI
X-RemovedCookies
X-CCM
Azure-InstanceId
X-Time-Microsecs
X-Cache-Config
X-Xfnlog-Site
X-Via-CDN
X-Www-Served-By
Azure-RegionName
X-Backend-Name
X-Rule
Azure-Version
Azure-SlotName
Azure-SiteName
Mn-Server-Ip
X-Akamai-Request-ID2
X-Routing-Service
HitType
X-Guploader-Uploadid
X-Zipkin-Id
X-Proxied
Pagespeed
X-TIME
X-CLOUD-TRACE-CONTEXT
X-App-Name
X-Cache-TTL
OT-Force-Account-Verify
Cache-Key
X-Parent-Response-Time
X-Shopify-Stage
X-Nginx-Cache
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Protected-By
X-Alternate-Cache-Key
Content-Script-Type
Vix-Hermes-Req-Id
X-Kong-Proxy-Latency
X-CACHE-KEY
X-Dynatrace-Js-Agent
X-Kong-Upstream-Latency
User-Cache-Control
Content-Style-Type
X-RateLimit-Limit
X-Edge-IP
X-Ezoic-Cdn
X-Correlation-ID
Accept-Language
L5d-Success-Class
X-BACKEND-TTL
X-Real-IP
Time
X-OVcl
X-OVcl-Cache
NtCoent-Length
X-Pc-Host
X-Pc-Date
LB
X-Cache-Backend
X-RTag
Ms-Operation-Id
X-PERF
X-ApacheServer
X-Real-Ip
X-Cdn-Forward
X-Front
AR-SID
X-Amz-Meta-Surrogate-Control
X-Webkit-Csp
X-Proto
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Cache
X-FB-TRIP-ID
X-Mshield-Cache-Status
X-Mrs-Age
X-GRACE
X-Content-Age
Section-Io-Cache
X-Varnish-Cacheable
X-Varnish-Beresp-Status
X-CDN-Forward
X-Debug-Cache
X-Varnish-Beresp-Grace
X-Hit
Country
X-Nc
X-Sucuri-ID
WZWS-RAY
Load-Balancing
X-Unique-ID
X-Ratelimit-Limit
Fusion-Content-Id
Ohc-File-Size
Fusion-Component-Id
X-Trace-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Microcachable
X-MP-GENERATED-AT
Version
X-Hl-Ver
X-C
X-Time
Access-Control-Request-Headers
X-Varnish-Beresp-Ttl
Mail-Subject
We-Hiring
X-EdgeConnect-Cache-Status
X-Datadome
X-Cache-Enabled
X-Connection-Hash
X-Transaction
X-Twitter-Response-Tags
Warning
X-Cache-FS-Status
X-Clientip
X-CF-Lambda-Version
X-Crawler
X-Returned-From-BeforeDispatch
X-CUA
X-CF-Lambda-Fn
X-Cache-URL
X-Cache-Bucket
X-Cache-Expires
X-Cache-Host
X-Cache-Id
X-Returned-From-DLL
X-Application
RNT-Machine
Resin-Trace
Rendered-Blocks
RNT-Time
Rt-Proxy-Cache
Server-ID
SD-X-WS
Release
Powered-By
Memcached
MD5-Digest
Is-Eu
Meta-Geo-Continent
Mobile-Detection-Method
Platform
Node
SS
V-Age
X-Aed
X-Actual-URL
X-Accel-Expires-Debug
X-Auto-Login
X-B-Cookie
X-BB-ID
X-Backend-State
X-A-Wwc
X-A-Dgt
Www
X-Returned-From-PostProcessResponse
Viewtype
X-A
X-A-Ccd
X-A-Dcw
X-A-Dam
X-Bip
X-DPWN-IS-SECURE
X-VG-WebServer
X-LI-Proto
X-Server-Time
X-LI-UUID
X-Varnish-Action
X-Logtrace-Id
X-Li-Pop
X-PAYTM-SRV-ID
X-PHP-Host
X-Served-From
X-Server-By
X-We-Are-Hiring
X-Via-Edge
X-Via-SSL
X-Node-Id
X-NU-AKA-ACS-Version
X-Trv-Group
X-UE-Client-Country
X-Thanos
X-Passed-To-DLL
X-Store
X-Passed-To-PostProcessResponse
X-User
X-SRCache-Key
X-Org
X-Variation
X-Passed-To
X-Passed-To-BeforeDispatch
IBM-Web2-Location
X-Var-Ttl
X-ScT
X-S-Maxage
X-F5-Cache
X-External-Request-Id
X-Rojux
X-Returned-From
X-S-Cookie
X-Response-By
X-Rewrite-Enabled
X-Swa-Ws
X-Destination
X-Date
X-Developer
X-Device-Os
X-Dispatcher-Server
X-Died
X-From
X-Request-UUID
X-Qloud-Router
X-RCS-CacheZone
X-Layer
Xc-Version
X-WebServer
X-Li-Fabric
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Release
X-G
X-Region-Sid
X-Reboot
X-GeoIP-Country-Code
X-Generated-In
X-D
VivaBuild
Ajk
Fastly-SWR
Frame-Options
Adler-Geo
User-Agent
Fastly-Backend-Name
Fastly-SIE
X-Ua
Ec-Rule-Version
Fly-Request-Id
Fly-Cache
BehaviorPad-Version
Cache-Prefix
Arc-Country
Countrycode
X-B3-Traceid
X-Dc
X-Eu-Site
X-FW-Version
X-Gen-Mode
X-Gannett-Site-Version
X-Fetched-On
X-CGP
Apple-News-Services-Parsed-Url
X-Amz-Meta-Cache-Control
Apple-News-Services-Request-Url
Backend
Backend-Name
Apple-News-Services-Host
Apple-News-Services-Handled
X-Hash
X-Cache-Debug
X-Block-Status
AKAMAI
X-Epic-Correlation-Id
X-IN-APIGATEWAY
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Stale
X-Sf
X-ServiceProvider
X-Thinkindot-L3
X-UnsetCookies
X-P-T
X-TT-LOGID
X-Goog-Meta-Goog-Reserved-File-Mtime
Request-Time
X-Via-NSCOPI
X-Server-IP
X-Server-Group
X-Key
X-Location
X-Info
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Matched-Rule
X-No-Session
X-Rocket-Nginx-Bypass
X-Secret
HA-Geocountry
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Hnp-Log
X-Request-Start
Origin
On-Server
GMS-Ver
GW-Server
Pramga
Proxy-Connection
Decoy-Debug-TTL
Server-Host
Esi-Enabled
Kp-EeAlive
HA-Cloudapp
Ha-Gx-Prefs
HA-Georegion
HA-Geolon
HA-Geolat
HA-Host
HA-Ipaddr
HA-Geocity
Heartbleed
HA-Servedtime
Thinkindot-CacheControl
HA-Urlpath
Country-Code
Thinkindot-Control
Thinkindot-CacheControl-Type
Web-Mar-Node
Who
True-Client-Country-4JS
Content-Disposition
Decoy-Debug-Key
Decoy-Debug-Status
X-Geo
X-NODE
Magicmarker
X-Policy
X-Wikidot-Static-Cache
Request-Country
Request-EU
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Uber-Trace-Id
Cache-Cookie-Set-Lfrom
Fastly-SSL
X-Irp-Debug
X-Urbn-Context-Path
X-MI-In-Market
CDCHOST
UCS
X-SIPLIST1
X-Urbn-Site-Id
X-V
X-Instance-Name
X-Wikidot-Backend
Server-Int
X-Backend-Url
IsBot
Pragrma
X-Cache-CFC
X-Planisys-CDN-TTL
X-Phone
MI-API
X-Request-URI
Locale
X-Core-Value
X-Up
MI-Cache-Age
X-Planisys-CDN-Cache
MI-Cache
PFcat
X-Planisys-CDN-Rules
X-Origin-Expires
X-Origin-Date
X-Page-Type
X-Distributor
Fastly-Soc-X-Request-Id
X-Platform
X-Fstrz
X-Backend-Host
X-Nginx-Cache-Key
X-Developers
X-MSEdge-Flight
X-MSEdge-Features
X-Distil-CS
X-DC
X-Be
X-SERVER
Pagetype
X-CACHE-AGE
X-Origin-TTL
PageSpeed
X-Refresh
X-Servername
X-NWS-UUID-VERIFY
X-Fastly-Cache
X-Core-Mission
X-Debug-Log
X-Debug-Cookies
X-Cdn-Origin
REQUESTUUID
X-ElasticPress-Search
X-Sn-Servicetimems
X-NX-Host
Group
V-Cache
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Svr
X-Debug-Cache-Expiry
X-VCT
X-COUNTRY
X-GeoIP-City
X-Micro-Cache
X-NC
HitInfo
X-PARISIEN-Cache-Rendered
Host-ID
RequestId
X-Instart-Info
X-VarnCache
X-Pjax-Url
X-VarnPar1
X-Req
X-Newrelic-Synthetics
X-Generated-On
ServerName
Lfy
MIME-Version
X-Level-Front-Cache
Ohc-Response-Time
X-Cache-Info
X-Server-Cache
X-Cdn-Srv
X-BBXSRF
X-Powered-By-ANYU
X-ARC
X-EIG-Tracking-Id
Cache-Provider
PICS-Label
Memory
Mime-Version
X-Gdpr
Cteonnt-Length
Cdn
X-TWH-CORRELATION-ID
X-CMS-Context
X-Servedbyhost
CF-IPCountry
Nel
X-LAGOON
X-Wa
X-StackifyID
X-Cluster-Node
X-WR-MODIFICATION
NGX
X-Fastly-Country-Code
X-Aicache-OS
CDN
X-Load-Cache
FSS-Cache
FSS-Proxy
GeoIP-Latitude
X-Sentry-ID
X-NodeID
X-HTML-Minification-Powered-By
GeoIP-Country-Code
X-Ratelimit-Remaining
X-Check-Cacheable
X-Hello
X-ABtesting
X-Flog
X-Fastly-Backend-Reqs
X-VServer
X-CSRF-TOKEN
Geoip-Latitude
XServer
GeoIp-Country-Code
X-Varnish-Beresp-TTL
SN
X-WA
X-FireWall-Port
X-GZip
Cf-Ipcountry
X-Source
X-APP
Processtime
X-UPSTREAM-Address
Amp-Access-Control-Allow-Source-Origin
X-Csrf-Token
TSSecure
X-Generation-Time
X-RateLimit-Remaining-Second
X-Unique-Id
X-HOST
X-Varnish-Cache-Hits
X-RateLimit-Limit-Second
X-CSRF-Token
CACHE
X-Sedo-Request-Id
X-DataStream-MidMile-RTT
X-Oss-Server-Time
WP-Super-Cache
X-Oss-Storage-Class
X-ServedByHost
X-Oss-Request-Id
X-Worker
X-CDN-Pop-IP
X-CDN-Pop
X-DataStream-Origin-MEX-Latency
X-Cache-Miss-From
X-MServer
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Edge-Server
A
Cdn-Host
X-Nananana
PageType
X-Dynatrace
X-Cache-Grace
URI
Cdn-Request-Time
X-SRV
X-GDPR
X-FORWARDED-FOR
Pics-Label
X-VC-Cache
X-Skip-Cache
X-AWS-Id
X-ID
X-VWS-Id
X-SplitTest
DataCenter
X-LJ-Flow-ID
X-Fastly-Cache-Hits
X-RCS-Backend
X-Varnish-Authentication
X-IPS-LoggedIn
Server-Surrogate-Control
X-Cache-ASPX
Server-Cache-Control
X-Sucuri-Cache
X-HS-Status
X-Port
HTTPS
X-Backend-TTL
X-BE
X-B3-SpanId
Odigeo-Trace-Id
X-Varnish-Url
X-VG-WebCache
Cache-Hits
X-Swift-Error
X-Owner
Hostname
Dynatrace
X-ND-Cache
X-Instart-Isnd
X-From-Cache
X-PJAX-URL
X-Gen-Id
Get-Access-Time
Requestid
Is-Session-Tracking
X-Bug-Bounty
X-Amzn-Remapped-Connection
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Version
X-Pf-Uncompressing
X-GZIP
X-SN
X-Ms-Blob-Type
X-Amzn-Remapped-Date
FastCGI-Cache
X-GoCache-CacheStatus
Proxy-Firewall
X-Server-W
ProcessTime
X-ORIG-AKA-EDGE
RequestUuid
X-Cache-Ttl
X-VarnPar2
X-NGINX-Cache
Serverid
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-LiteSpeed-Cache-Control
X-ServerName
X-Fe
X-Varnish-URL
Powered
X-Serial
X-Alicdn-Da-Ups-Status
X-PAGE-TYPE
X-RAMCache
WebServer
X-ORIG-AKA-COUNTRY-CODE
X-Ms-Lease-State
X-GEO
T-Server
Accept-Ch
X-VC
X-SB
X-Cache-Srv
Xet-Cookie
SID
X-HTML-Edge-Cache
X-PF-Uncompressing
Correlation-Id
X-CS
X-LiteSpeed-Tag
X-Akamai-ERPolicy
X-Developed-By
NnCoection
X-Dw-Trace-Id
Location
NodeID
X-Akamai-ERRuleID